CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-50125
5.9 MEDIUM

A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed state.

Jan 11, 2024
CVE-2023-50124
6.8 MEDIUM

Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design …

Jan 11, 2024
CVE-2024-0425
5.3 MEDIUM

A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipulation leads …

Jan 11, 2024
CVE-2024-0419
5.3 MEDIUM

A vulnerability was found in Jasper httpdx up to 1.5.4 and classified as problematic. This issue affects some unknown processing of the component HTTP POST …

Jan 11, 2024
CVE-2024-0418
5.3 MEDIUM

A vulnerability has been found in iSharer and upRedSun File Sharing Wizard up to 1.5.0 and classified as problematic. This vulnerability affects unknown code of …

Jan 11, 2024
CVE-2024-0417
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in DeShang DSShop up to 2.1.5. This affects an unknown part of the file application/home/controller/MemberAuth.php. The …

Jan 11, 2024
CVE-2024-0416
5.4 MEDIUM

A vulnerability, which was classified as critical, has been found in DeShang DSMall up to 5.0.3. Affected by this issue is some unknown functionality of …

Jan 11, 2024
CVE-2024-0415
6.3 MEDIUM

A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the file application/home/controller/TaobaoExport.php …

Jan 11, 2024
CVE-2024-0414
5.3 MEDIUM

A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation …

Jan 11, 2024
CVE-2024-0413
5.3 MEDIUM

A vulnerability was found in DeShang DSKMS up to 3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file …

Jan 11, 2024
CVE-2024-0412
5.3 MEDIUM

A vulnerability was found in DeShang DSShop up to 3.1.0. It has been declared as problematic. This vulnerability affects unknown code of the file public/install.php …

Jan 11, 2024
CVE-2024-0411
5.3 MEDIUM

A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown part of the file public/install.php …

Jan 11, 2024
CVE-2023-6554
6.5 MEDIUM

When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to …

Jan 11, 2024
CVE-2023-5118
5.4 MEDIUM

The application is vulnerable to Stored Cross-Site Scripting (XSS) in the endpoint /sofer/DocumentService.asc/SaveAnnotation, where input data transmitted via the POST method in the parameters author …

Jan 11, 2024
CVE-2023-6938
6.4 MEDIUM

The Oxygen Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom field in all versions up to, and including, 4.8 due …

Jan 11, 2024
CVE-2023-6244
6.5 MEDIUM

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 …

Jan 11, 2024
CVE-2023-6242
6.5 MEDIUM

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 …

Jan 11, 2024
CVE-2023-51751
6.8 MEDIUM

ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching …

Jan 11, 2024
CVE-2023-51750
4.6 MEDIUM

ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the …

Jan 11, 2024
CVE-2023-7071
6.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents …

Jan 11, 2024
CVE-2023-7070
6.4 MEDIUM

The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's eeb_mailto shortcode in …

Jan 11, 2024
CVE-2023-7019
4.3 MEDIUM

The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Jan 11, 2024
CVE-2023-6994
6.4 MEDIUM

The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' shortcode in all versions up to, and including, …

Jan 11, 2024
CVE-2023-6990
5.4 MEDIUM

The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions up to, and including, 6.3.0 due …

Jan 11, 2024
CVE-2023-6988
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_builder_render_js shortcode in all versions up to, and including, …

Jan 11, 2024
CVE-2023-6934
6.4 MEDIUM

The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, …

Jan 11, 2024
CVE-2023-6924
4.4 MEDIUM

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to …

Jan 11, 2024
CVE-2023-6882
6.1 MEDIUM

The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ parameter in all versions up to, and including, 4.3.8 due …

Jan 11, 2024
CVE-2023-6855
5.3 MEDIUM

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by …

Jan 11, 2024
CVE-2023-6782
6.4 MEDIUM

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up …

Jan 11, 2024
CVE-2023-6781
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and …

Jan 11, 2024
CVE-2023-6776
6.4 MEDIUM

The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all versions up to, and including, 1.15.2 …

Jan 11, 2024
CVE-2023-6742
4.3 MEDIUM

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check …

Jan 11, 2024
CVE-2023-6737
4.7 MEDIUM

The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG parameter in all versions up to, and including, 4.1.4 …

Jan 11, 2024
CVE-2023-6684
6.4 MEDIUM

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' shortcode in versions up to, and including, …

Jan 11, 2024
CVE-2023-6645
6.4 MEDIUM

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions …

Jan 11, 2024
CVE-2023-6638
6.5 MEDIUM

The GTG Product Feed for Shopping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_settings' …

Jan 11, 2024
CVE-2023-6637
6.5 MEDIUM

The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Jan 11, 2024
CVE-2023-6632
6.1 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions …

Jan 11, 2024
CVE-2023-6624
4.9 MEDIUM

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, …

Jan 11, 2024
CVE-2023-6598
4.3 MEDIUM

The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the speedycache_save_varniship, speedycache_img_update_settings, speedycache_preloading_add_settings, and speedycache_preloading_delete_resource …

Jan 11, 2024
CVE-2023-6583
6.6 MEDIUM

The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the …

Jan 11, 2024
CVE-2023-6582
5.3 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. …

Jan 11, 2024
CVE-2023-6561
6.4 MEDIUM

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured image alt text in all versions up …

Jan 11, 2024
CVE-2023-6556
5.4 MEDIUM

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, …

Jan 11, 2024
CVE-2023-6504
4.3 MEDIUM

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data …

Jan 11, 2024
CVE-2023-6496
5.3 MEDIUM

The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_famne_export_settings function. This …

Jan 11, 2024
CVE-2023-6369
5.4 MEDIUM

The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing …

Jan 11, 2024
CVE-2023-5691
4.4 MEDIUM

The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 2.3.9 due to insufficient input sanitization and …

Jan 11, 2024
CVE-2023-4962
6.4 MEDIUM

The Video PopUp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'video_popup' shortcode in versions up to, and including, 1.1.3 due to insufficient …

Jan 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.